[saag] Re: [nasr] Re: Re: NASR BOF Follow-Up

Michael Richardson <[email protected]>
Newsgroups gmane.ietf.saag
Message-ID <[email protected]>
Eric Rescorla <[email protected]> wrote:
    > However, it's not clear to me that that's true in this case, because
    > unlike media players, network devices are highly configurable and a
    > large number of the configuration directives might impact the relevant
    > security claims. Thus, determining whether an element is policy
    > conformant is a matter of knowing not just what code it is running
    > but the state of every relevant configuration directive. One could
    > imagine this working at least three ways:

I think you are making routers sound way more complicated than they are.

1. 90% of directives have little to no affect.
   (I have one toe in the routing/operations space. I'm ASN26227)

2. they are significantly less complicated than Windows, yet all that media
   based DRM stuff you mentioned is dependant upon windows boot doing the
   right thing.

3. the routers in question are usually controlled almost entirely via
   SDN/YANG.  As such, there are *significantly* fewer variations in
   configuration than there used to be.

Yes, you can probably get JUNOS (which is a FreeBSD kernel) to run a
minecraft server.   And they even have enough RAM to do so.
But, that's not a configuration that we would expect.

80% of "is valid configuration" probably amounts to: are there any mirror
ports enabled?

    > In the former case, it is quite likely that there will be a large
    > number of valid states, because each directive may have multiple
    > acceptable values, and so you end up with combinatoric explosion
    > issues if you just have a list of hashes [0]. In the latter case we

yet, the *routing* people with the expertise here, and a few operators seem
pretty sure they can do this.

    > Either approach requires studying the impact of every existing
    > configuration directive for each device type to know what the
    > impact will be on the relevant policy claims. This seems challenging
    > at best.

--
Michael Richardson <[email protected]>   . o O ( IPv6 IøT consulting )
           Sandelman Software Works Inc, Ottawa and Worldwide

_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]
signature.asc (application/pgp-signature, 515 B)
-----BEGIN PGP SIGNATURE-----

iQFKBAEBCgA0FiEEbsyLEzg/qUTA43uogItw+93Q3WUFAmfy2OcWHG1jcitpZXRm
QHNhbmRlbG1hbi5jYQAKCRCAi3D73dDdZYToCACn+8nIVpOkDO07X3WiKtWx/ztd
zz2hIUPSDK+ITJhT2dgQi/zbN8VAAiru7eN0rl1c3oAiQC30ddX0czUUZwdg/159
KcMcXfEkso/kzi9df3IKKPiq/cHm5EvySGQVCwvkNfp7XvwTI2J2lKZT9nGpYKla
WVyfUpw6NXNSdS8g5stcz4k+GasrsCO+Y7LpZtrprbOHN28+7UN4jTKGjMR+BR8q
mN7Bd9QAxeXNqQV+Kbh6v9pupwAMLpWNmpUi3NaJThOPiIhGbBlfMHV0pDHzEfaH
+Ws/dsazMS5rrzzPECdTL06e8li0qZlUtvMq1GlenZ+/9NkqUvK9hNuJhp9P
=a5vK
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.